Senior Security Engineer

CyraCom
Overland Park, KS, United States
6 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$104,400.0 - $149,270.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Cloud Computing Security CompTIA Network+ Cyber Security Continuous Integration Data Integrity Dynamic Host Configuration Protocol Domain Name System (DNS) Intrusion Detection Systems Log Analysis Microsoft Security Essentials Networking Basics
+11 more
Security Information and Event Management Software Engineering Virtual Local Area Networks Software Vulnerability Management Software Security Firewalls (Computer Science) Information Technology Devsecops Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

We are seeking a Senior Security Engineer to join our team. They will be a key member of the Information Security department, responsible for performing cybersecurity risk mitigation activities and ensuring the security of Propio’s infrastructure. This role involves leveraging industry-leading technologies to identify and respond to threats, conducting analysis of security-related data, and providing incident response support with minimal oversight and may direct other resources when engaged in larger efforts, when required. This role is a DevSecOps Engineer at its core., Cloud Security

  • Lead the evaluation and implementation of new cloud security tools and processes to enable a secure cloud architecture (strong background in AWS is required)
  • Develop and automate cloud security controls to identify and mitigate security threats and violations, including proactive identification of security risks
  • Support evidence collection from cloud security controls to support compliance efforts
  • Proactively work with other departments to remediate critical security vulnerabilities and resolve complex security problems often requiring additional research
  • Work with engineering teams to secure the automated build, test, and deployment processes of our CI/CD pipeline and Infrastructure as Code.

Application Security

  • Ensure security is integrated into software development through use of key tools such as SAST, DAST, SCA, threat modeling, API security, and vulnerability scanners.
  • Evaluate vulnerabilities using threat intelligence, exploitability, asset criticality, and business impact to provide risk-based recommendations and support informed decision-making
  • Partner with technology departments to drive remediation efforts, including the use of artificial intelligence, where approved, to speed up mean time to remediate
  • Advance the vulnerability management strategy and automation capabilities to meet the challenges of the evolving threat landscape

Incident Response

  • Analyze logs from various security controls, including firewalls, proxies, intrusion prevention systems, and endpoint security solutions, to detect potential threats
  • Safely acquire and preserve data integrity for cyber incident analysis, determining the technical and operational impact, root causes, and scope of incidents
  • Provide escalated incident response support, as needed, including analysis of security alerts and communication with stakeholders
  • Liaise with IT teams during incident response and alert triaging, as well as with other internal or external stakeholders, when directed, during remediation scenarios

Requirements

  • 12+ years of IT and/or information security work experience, including administration, analysis, or engineering roles; or combination of experience and relevant education, such as a bachelor’s degree in computer science or information assurance
  • Relevant IT security certification is highly desirable, such as CompTIA A+, CompTIA Network+, GIAC Security Essentials, CISSP, and/or CCSP.
  • Strong knowledge of various security methodologies, processes, and technical solutions such as SIEM, IDS/IPS, Firewall Solutions, and Offensive Security tools
  • Experienced with HIPAA-specific security requirements
  • Advanced understanding of network concepts (DHCP, DNS, VLANs, etc.)
  • Successfully performed in senior DevSecOps role
  • Ability to think critically and logically under pressure and work in a fast-paced environment
  • Ability to lead others on technical and administrative tasks
  • Strong technical experience with a proven history of troubleshooting complex problems across different segments, offices, and teams
  • Ability to mentor less experienced personnel to learn and grow professionally

Benefits & conditions

  • $195,000 per year Are you looking for an exciting new opportunity? Join a global financial markets infrastructure provider delivering trusted trading, exchange, and market technology solutions acr…

  • 19 days ago + *

About the company

Propio Language Services is a provider of the highest quality interpretation, translation, and localization services. Our people take pride in every resource we offer, and our users always have access to the best technology, support, and experience. We are driven by our passion for innovation, growth, and connecting people. If you believe in the transformative power of technology-driven solutions and meaningful communication, Propio could be the ideal place for you., Ascend Learning

  • Leawood, KS
  • $104,400-149,270 per year We Impact Lives Through Purpose-Driven Work in A People First Culture Ascend Learning, a leading healthcare and learning technology company, is the connection between a powerful …

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all